The Orthopaedic Institute of Western Kentucky (OIWK) experienced a data breach that was initially detected on December 15, 2025, due to a ransomware attack on its IT systems. The breach was publicly disclosed in early 2026 with notifications to affected individuals beginning in February 2026. Official sources include the HHS Office for Civil Rights (OCR) Breach Portal, the Kentucky AG Data Breach Portal, and OIWK's website notice.
Approximately 47,000 individuals were affected by this incident. The types of data exposed include names, addresses, dates of birth, medical information (such as treatment records and diagnoses), health insurance information, and Social Security numbers for a subset of the victims. No financial account numbers were reported as compromised. The states primarily affected were Kentucky, with smaller numbers in Tennessee, Illinois, Missouri, and Indiana.
Details about data breaches can emerge over time, and notification processes may experience delays.